Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Provides iCalendar (RFC5545) parsing as well as a convenient API for generating iCalendar data.
You can generate a single event:
var event = new icalendar.VEvent('cded25be-3d7a-45e2-b8fe-8d10c1f8e5a9');
event.setSummary("Test calendar event");
event.setDate(new Date(2011,11,1,17,0,0), new Date(2011,11,1,18,0,0));
event.toString();
Or create a collection of events:
var ical = new icalendar.iCalendar();
ical.addComponent(event);
var event2 = ical.addComponent('VEVENT');
event2.setSummary("Second test event");
event2.setDate(new Date(2011,11,5,12,0,0), 60*60); // Duration in seconds
Create a iCalendar collection from a string:
// data is a string containing RFC5545 data
var ical = icalendar.parse_calendar(data);
Access an array of the events defined within:
ical.events()
Several portions of the iCalendar spec remain unimplemented:
* HOURLY, MINUTELY, and SECONDLY recurrence are not implemented.
- Support for these is not currently planned, as they do not
seem to be found in actual use.
* BYHOUR, BYMINUTE, and BYSECOND modifiers are not implement as above.
* BYSETPOS
* WKST
- This could very likely become important
* BYWEEKNO
* BYYEARDAY
* RDATE is not yet implemented
* RECURRENCE-ID and multiple related VEVENTS are not currently supported
* Documentation is pretty weak
FAQs
RFC5545 iCalendar parser/generator
We found that icalendar demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.